Skip to content

Protecting the data a church holds about its members

A church knows addresses, giving, children's allergies, and confessed sin. Who gets to see what, where counseling notes must never live, and the breach plan an elder board can write in an hour.

Church Posting Jul 28, 2026 6 min read Theology


Working on a laptop with a security prompt
Photograph by Rafael Minguet Delgado on Pexels

Your church database knows where the widow lives alone, which child has an epinephrine pen, which household gave $40,000 last year, and which marriage nearly ended in March. A retailer holding this much would face an audit. Most congregations hold it in a system where four staff logins share one password and nobody has reviewed permissions since the software was installed.

This is a pastoral problem carried by a technical system. The membership roll is a record of souls under care, and a member who learns their giving amount was mentioned in a staff meeting has learned something true about how the church regards them.

Sort what you hold into four tiers

Write the list. Everything the church stores about a person goes into one of these, and the tier determines who can see it.

Tier one, directory information. Name, household, address, phone, email, birthday, membership date. Visible to staff and to members through a directory, if members have consented to appear in it. Ask before publishing anyone. A woman who left an abusive marriage has a reason to be unlisted, and she should not have to explain it to the church secretary.

Tier two, operational records. Attendance, serving assignments, group membership, children’s check-in and allergy notes, background check status. Visible to staff and to the specific leaders who need it. The children’s director sees allergies. The finance committee does not.

Tier three, financial records. Giving amounts by name, pledges, benevolence received. Visible to the financial secretary and to whichever officer your governing documents specify, and to nobody else by default. Many congregations deliberately keep the preaching elder out of this record entirely so that no sermon can be suspected of following the money. That is a decision your elders should make on purpose and write down, rather than inherit from whatever the software defaulted to.

Tier four, pastoral and confidential. Counseling notes, discipline proceedings, disclosures of sin, abuse reports, health crises. This tier does not belong in your church management system at all.

The rule about counseling notes

Do not put counseling notes in the ChMS. Not in a custom field, not in the notes tab, not marked private.

Three reasons, and any one is sufficient.

The permission model is not built for it. Note privacy in most church software is a checkbox, and a checkbox is one administrator’s mistake away from being visible in a report, an export, or a merged household record.

Exports are indiscriminate. The day you migrate to a new system, everything comes out in a CSV that sits in someone’s downloads folder.

Legal exposure runs both directions. Notes stored in a shared system are harder to defend as confidential, and their absence is harder to explain if a court asks what the church knew. Talk to an attorney in your state about how clergy confidentiality and mandatory reporting apply to your situation, and then write your own policy. Do not take a policy from the internet, including this page, as legal advice.

What to do instead: keep pastoral notes minimal, on paper, in a locked drawer in the office of the person who wrote them, with a written retention period. Abuse reports follow your state’s mandatory reporting law immediately, and that is a separate track from anything described here.

Twelve controls that cover most of the risk

None of these require a consultant.

  1. Every person has their own login. Shared accounts make every action untraceable and survive every staff departure.
  2. Two-factor authentication on the ChMS, the giving platform, the email account, and the domain registrar. Those four, at minimum, today.
  3. A church-owned password manager. One vault, church billing, two administrators. Passwords in a shared Google Sheet are the most common serious weakness in a church office.
  4. Written offboarding. The day someone leaves staff or rotates off a team, a named person removes their access from every system on a checklist. Do this for volunteers too, especially children’s check-in.
  5. Quarterly permission review. Print the user list, read it out loud in a staff meeting, and remove people. It takes ten minutes and it always finds something.
  6. Church-owned accounts for everything. The website, the domain, the streaming channel, the social accounts, the Google or Microsoft tenant. Anything registered to a personal address is one resignation away from being lost.
  7. Restrict giving visibility by policy, not by trust. Set it in the software so the question never comes up.
  8. Do not store payment card numbers. Ever, anywhere, including a paper file of authorization forms in a drawer. Let the processor hold them.
  9. Background check documents live in one locked place with a retention period. They contain the most sensitive information about your volunteers and they are often the least protected file in the building.
  10. Children’s check-in data gets a purge schedule. You do not need last year’s pickup codes.
  11. A real backup you have tested. Export the full database quarterly to encrypted church-owned storage, and once a year actually open the file and confirm the data is in it.
  12. Devices with a lock screen. The office laptop and the check-in tablets. A tablet left unlocked in a lobby is your whole children’s roster.

Members should know what you collect and what you do with it. One paragraph on the website and in the membership packet:

What you collect, why you collect it, who inside the church can see it, what appears in the directory, whether the directory is printed or online, how to be excluded, how to correct a record, and how to be removed after leaving.

Then honor it. Do not add a visitor to the all-church email list because they filled out a prayer card. Do not sell, trade, or share the roll with anyone outside the church, including denominational bodies, without asking. Do not publish photographs of children without written parental permission on file, and keep a list of the families who said no where the person posting to social media will actually see it.

The breach plan, written before you need it

One page, approved by the elders, kept where the office can find it. Six lines:

  • Who to call first. One named person with a phone number. Usually the administrator, with the chairman of elders as backup.
  • Contain. Reset the affected passwords, revoke the affected sessions, take the affected system offline if needed.
  • Preserve. Do not delete anything. Screenshot what you saw, note the time, keep the logs.
  • Determine scope. Which tier of data, how many people, over what window.
  • Notify. State breach notification laws apply to churches in most states and the timelines are short. Have counsel identified in advance rather than searching for one during the incident.
  • Tell the congregation the truth, promptly, in plain words. What happened, what was exposed, what you are doing, what they should do. A church that hides a breach loses far more than the data.

What this is protecting

A church asks its people to be known. Membership means the elders keep a list with your name on it, that someone notices when you are absent, that your sin is not a private matter, and that your household is under care. That request only holds if the church is trustworthy with what it learns.

Every control above exists so that a member can tell the truth in this room without wondering where it goes. Set the permissions this month, and the harder conversations get easier for years.

For the office systems these records live in, start with choosing church management software, and for the donation side see what giving platforms actually cost.


Back to top